US Sanctions Iran's Strait of Hormuz Bitcoin Insurance Scheme: What Accounting Firms and CFOs Must Act On Now
The US Treasury's Office of Foreign Assets Control (OFAC) has designated a network of companies linked to an Iranian scheme that used Bitcoin to underwrite insurance coverage for vessels transiting the Strait of Hormuz. The action, published on 30 July 2026, targets firms that allegedly helped Iran generate hard-currency revenue and circumvent existing sanctions by routing premiums and payouts through Bitcoin rather than the conventional correspondent-banking system. For accounting firms, auditors, and CFOs with any exposure to digital asset transactions or maritime trade finance, the designations carry immediate screening and record-keeping obligations.
What the Scheme Involved
Iran's access to international insurance markets has been severely restricted by sanctions for years. Maritime operators transiting the Strait of Hormuz, one of the world's most strategically significant waterways for energy shipments, need hull and cargo coverage. The scheme identified by OFAC appears to have exploited that gap by offering Bitcoin-denominated insurance products, allowing vessels to obtain coverage without touching the US dollar financial system or dealing with sanctioned Iranian insurers through conventional channels.
How Bitcoin Was Used as the Settlement Rail
Rather than routing premiums through banks, the designated entities allegedly collected and disbursed funds in Bitcoin. This approach was designed to sidestep the transaction monitoring that banks apply under Bank Secrecy Act obligations and OFAC's own sanctions compliance programs. Using a pseudonymous settlement layer does not, however, remove the underlying sanctions exposure: any US person or entity that transacts with a designated party, regardless of the currency or asset used, risks violating the International Emergency Economic Powers Act (IEEPA) and related executive orders.
The Designated Entities
OFAC's action targets the specific companies and individuals identified as operating or facilitating the scheme. Their names now appear on the Specially Designated Nationals and Blocked Persons (SDN) list, meaning that all property and interests in property subject to US jurisdiction are blocked, and US persons are generally prohibited from transacting with them. Counterparties outside the US also face secondary sanctions risk if they continue to deal with the listed parties.
Sanctions Exposure for Firms Handling Digital Asset Transactions
The Hormuz scheme is a reminder that sanctions evasion through crypto is not theoretical. OFAC has now sanctioned actors using Bitcoin in insurance, stablecoins in arms financing, and privacy coins in ransomware settlement. Each action expands the precedent that the asset class does not confer immunity from US extraterritorial reach.
Who Is at Risk
The risk perimeter is broader than it might first appear. Accounting firms advising clients in shipping, energy trading, or commodities need to assess whether any counterparty in their client's transaction chain obtained maritime insurance through non-standard channels and paid for it in crypto. CFOs at companies with treasury operations that include Bitcoin or other digital assets need to verify that their wallet-screening and transaction-monitoring controls would catch an inbound payment from a newly designated wallet address. Auditors reviewing digital asset balances must confirm that the entity's SDN screening was current at the time of each transaction.
The Correspondent Banking Parallel
Regulators and enforcement agencies treat Bitcoin rails and correspondent bank rails equivalently when it comes to sanctions. Just as a bank that processes a wire for a sanctioned entity cannot rely on ignorance as a defence, a company that receives Bitcoin from a wallet controlled by an SDN-listed entity faces strict liability exposure. The absence of a human intermediary does not reduce the legal risk; it may actually increase it, because automated settlement can complete before any compliance check fires.
Accounting and Record-Keeping Obligations
From an accounting standpoint, any digital asset transaction that is later found to involve a sanctioned party creates a cascade of problems. The transaction cannot simply be reversed or written off; it must be disclosed, the asset must be blocked (if still held), and the firm may need to file a report with OFAC. These are not merely legal obligations; they affect the integrity of financial statements.
Blocking and Reporting Under OFAC Rules
When a US person holds or controls property in which a designated party has an interest, that property must be blocked, segregated, and reported to OFAC within ten business days. For a digital asset, that means the relevant wallet balance or token holdings must be quarantined and cannot be used, transferred, or otherwise dealt with until OFAC grants a licence. Failure to block and report is itself a sanctions violation, separate from the underlying transaction that created the exposure.
Implications for Digital Asset Accounting Software
Firms relying on crypto accounting software or digital asset accounting software to manage client books need to confirm that their chosen tooling pulls from current SDN list data and flags wallet addresses associated with designated entities. A platform that reconciles transactions but does not cross-reference on-chain addresses against OFAC's SDN list leaves a material compliance gap. This is not a feature that can be deferred; it is a baseline control that regulators expect to be in place before a transaction is accepted, not after the fact.
Crypto bookkeeping software that logs Bitcoin receipts and disbursements must also retain the transaction metadata, counterparty wallet addresses, timestamps, and any available KYC data in a form that can be produced in the event of a regulatory examination. OFAC examinations increasingly involve on-chain analytics, and firms that cannot reconstruct their transaction history from their own records are at a disadvantage before the review even begins.
AML and KYC Implications
The Hormuz scheme illustrates a recurring pattern: sanctions-designated actors use Bitcoin specifically because many of the firms they transact with have weaker screening controls for crypto than for fiat. That gap is closing, but it has not closed entirely.
What Robust Screening Looks Like
Effective AML controls for digital asset transactions include real-time or near-real-time wallet screening against updated SDN data, automated transaction-value thresholds that trigger enhanced due diligence, and a documented escalation path when a match is identified. For accounting and advisory firms, the equivalent obligation is to ensure that clients receiving professional services related to digital asset transactions have adequate controls in place, and to document that assessment. A firm that helps a client reconcile its Bitcoin treasury without ever asking about the client's own screening program is taking on an undefined risk.
Secondary Sanctions and Non-US Counterparties
Non-US firms that process, insure, or account for maritime transactions involving the Strait of Hormuz should treat this action as a prompt to review their own counterparty lists. OFAC's secondary sanctions authority means that non-US entities risk losing access to the US financial system if they provide material support to designated parties. For a global accounting network or a multinational CFO function, the practical implication is that a client relationship that touches any of the newly designated entities must be reviewed and, if necessary, terminated or reported before the relationship creates a secondary exposure.
See our earlier analysis of the OFAC action against the Hamas financing network for a broader picture of how Treasury designates crypto-linked nodes, and our breakdown of how sanctions and blockchain analytics collapsed a ruble stablecoin for a case study in how on-chain evidence is assembled post-designation.
Practical Steps for Accounting Firms and CFOs
The day a new SDN designation is published is the day existing controls are tested. The following steps are grounded in standard OFAC compliance practice and should be worked through systematically.
Immediate Actions
First, pull the full designation details from the official OFAC SDN list update and distribute them to anyone in the firm who screens counterparties or manages digital asset accounts. Second, run the newly listed wallet addresses and entity names against your current client and counterparty database. Third, if any match is found, do not move funds; consult sanctions counsel and initiate the blocking and reporting process. Fourth, document the screening run itself, the date, the tool used, the result, and who reviewed it. That documentation is your first line of defence in any subsequent examination.
Ongoing Controls
Beyond the immediate review, accounting firms and CFOs should confirm that their crypto accounting software or digital asset accounting software provider updates its sanctions data at least daily and that the update cadence is contractually specified and auditable. Quarterly reviews of the overall sanctions compliance framework, including the procedures for digital assets, are increasingly expected by regulators and are becoming a standard element of internal audit programs for firms with meaningful digital asset exposure.
Why This Action Matters Beyond Iran
Every OFAC crypto enforcement action builds the body of precedent that shapes how the next one is handled. The Hormuz scheme is notable because it involves a novel application of Bitcoin, not as a speculative asset or a payment rail for consumer purchases, but as the backbone of a structured financial product, specifically insurance. That application demands that compliance teams look beyond the obvious use cases when assessing crypto-related client relationships. If Bitcoin can be used to underwrite maritime insurance in a sanctions-evasion context, the same logic can be applied to trade finance, commodities derivatives, and other structured instruments.
Accounting and compliance professionals who treat crypto as a narrow, ring-fenced category will consistently be behind the enforcement curve. The more durable approach is to apply the same substance-over-form analysis to digital asset transactions that is applied to any other financial instrument: who is the economic counterparty, what is the ultimate source and destination of value, and does any link in the chain touch a sanctioned person or jurisdiction.
Source: Protos
FAQ
Any property in which the designated party has an interest must be blocked immediately, meaning it cannot be transferred, used, or otherwise dealt with. The firm must report the blocked property to OFAC within ten business days. Using, transferring, or failing to block the asset are all separate violations under US sanctions law.
No. OFAC's sanctions apply to any transaction that involves a US person or US-jurisdiction property, regardless of the currency or asset class. Bitcoin transactions with SDN-listed entities carry the same strict liability as dollar wire transfers.
At a minimum, digital asset accounting software should cross-reference wallet addresses against the current OFAC SDN list, update that data at least daily, generate an auditable log of each screening run, and flag any match for human review before a transaction is recorded or settled.
Potentially, yes. OFAC's secondary sanctions authority can restrict non-US entities from accessing the US financial system if they provide material support to designated parties. Non-US firms with maritime, energy, or digital asset clients should review their counterparty lists against the new designations.
Firms should record the date of the screening, the tool or data source used, the specific names and wallet addresses checked, the result of the check, and the name of the person who reviewed and approved the outcome. This documentation supports both internal audit and any external regulatory examination.
